inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie v", "url": "https://ghostwire.news/cve/CVE-2026-6019", "datePublished": "2026-04-22T20:16:42.617Z", "dateModified": "2026-04-22T21:23:52.620Z", "publisher": {"@type": "Organization", "name": "Ghostwire", "url": "https://ghostwire.news"}, "about": { "@type": "SoftwareApplication", "name": "CVE-2026-6019", "applicationCategory": "SecurityVulnerability" }, "proficiencyLevel": "Expert" }
Ghostwire

CVE-2026-6019: http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It...

UNKNOWN CVSS 0.0 Exploit Available 2 PoC

Published: April 22, 2026 | Last Modified: April 22, 2026

Description

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (2)

Security Coverage (1 articles)

References